Количество 3
Количество 3
CVE-2024-25153
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.
GHSA-4cvq-vvgx-cv87
A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells.
BDU:2024-02123
Уязвимость компонента ftpservlet программного средства для организации файлового обмена FileCatalyst Workflow, позволяющая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-25153 A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells. | CVSS3: 9.8 | 82% Высокий | почти 2 года назад | |
GHSA-4cvq-vvgx-cv87 A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a specially crafted POST request. In situations where a file is successfully uploaded to web portal’s DocumentRoot, specially crafted JSP files could be used to execute code, including web shells. | CVSS3: 9.8 | 82% Высокий | почти 2 года назад | |
BDU:2024-02123 Уязвимость компонента ftpservlet программного средства для организации файлового обмена FileCatalyst Workflow, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 82% Высокий | почти 2 года назад |
Уязвимостей на страницу